4.3

CVE-2021-22924

Exploit

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.

Data is provided by the National Vulnerability Database (NVD)
HaxxLibcurl Version >= 7.10.4 < 7.77.0
FedoraprojectFedora Version33
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
NetappCloud Backup Version-
OracleMysql Server Version >= 5.7.0 <= 5.7.36
OracleMysql Server Version >= 8.0.0 <= 8.0.26
SiemensScalance M804pb Firmware Version < 7.1
   SiemensScalance M804pb Version-
SiemensScalance M812-1 Firmware Version < 7.1
   SiemensScalance M812-1 Version-
SiemensScalance M816-1 Firmware Version < 7.1
   SiemensScalance M816-1 Version-
SiemensScalance M826-2 Firmware Version < 7.1
   SiemensScalance M826-2 Version-
SiemensScalance M874-2 Firmware Version < 7.1
   SiemensScalance M874-2 Version-
SiemensScalance M874-3 Firmware Version < 7.1
   SiemensScalance M874-3 Version-
SiemensScalance M876-3 Firmware Version < 7.1
   SiemensScalance M876-3 Version-
SiemensScalance M876-4 Firmware Version < 7.1
   SiemensScalance M876-4 Version-
SiemensScalance Mum856-1 Firmware Version < 7.1
   SiemensScalance Mum856-1 Version-
SiemensScalance S615 Firmware Version < 7.1
   SiemensScalance S615 Version-
SiemensSimatic Cp 1543-1 Firmware Version < 3.0.22
   SiemensSimatic Cp 1543-1 Version-
SiemensSimatic Cp 1545-1 Firmware Version < 1.1
   SiemensSimatic Cp 1545-1 Version-
SiemensSimatic Rtu3010c Firmware Version < 5.0.14
   SiemensSimatic Rtu3010c Version-
SiemensSimatic Rtu3030c Firmware Version < 5.0.14
   SiemensSimatic Rtu3030c Version-
SiemensSimatic Rtu3031c Firmware Version < 5.0.14
   SiemensSimatic Rtu3031c Version-
SiemensSimatic Rtu 3041c Firmware Version < 5.0.14
   SiemensSimatic Rtu 3041c Version-
SiemensSinema Remote Connect Version < 3.1
SiemensSiplus Net Cp 1543-1 Firmware Version < 3.0.22
   SiemensSiplus Net Cp 1543-1 Version-
SplunkUniversal Forwarder Version >= 8.2.0 < 8.2.12
SplunkUniversal Forwarder Version >= 9.0.0 < 9.0.6
SplunkUniversal Forwarder Version9.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.722
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://hackerone.com/reports/1223565
Patch
Third Party Advisory
Exploit
Issue Tracking